Joe_Williams
7 years agoProfessor
SDT EventSources
It would be nice from time to time to be able to SDT EventSources. We use Syslog and once in awhile it would be nice to be able to "ignore" all Syslog events from a specific device.
Have you tried enabling rate-limiting? At least until it all gets sorted out - I'd consider setting up a duplicate escalation chain and an alert rule specifically for some of your syslog eventsources and enable rate-limiting on them. Before my LogicMonitor days, I had this happen a few times and it sucks dealing with a crippled Exchange server while also trying to work out a firewall issue. Syslog is unpredictable sometimes.